First published: Thu Apr 04 2019(Updated: )
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jupyter Notebook | <5.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10856 is a vulnerability in Jupyter Notebook before version 5.7.8 that allows for an open redirect via an empty netloc.
CVE-2019-10856 has a severity rating of 6.1, which is considered medium.
To fix CVE-2019-10856, update Jupyter Notebook to version 5.7.8 or later.
The CWE of CVE-2019-10856 is CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')).
You can find more information about CVE-2019-10856 at the following references: [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-10856), [Jupyter Blog](https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4), [GitHub Advisory](https://github.com/advisories/GHSA-rcx2-m7jp-p9wj).